Commit Graph

294 Commits

Author SHA1 Message Date
can1357 b778617178 chore: reformat + rewrite changelogs 2026-07-28 11:19:34 +02:00
can1357 f0db9aa816 fix(utils): base child-shell filtering on real launcher values
Compiled Bun binaries autoload project dotenv files, so snapshotting Bun.env inside one captured the secrets as launcher-owned and forwarded them to every shell. Drop that branch and record launcher values, restoring an empty launcher value that Bun overwrote with a dotenv secret.
2026-07-28 10:58:59 +02:00
can1357 532e4c318c fix(utils): filter NODE_ENV dotenv files and keep escaped quotes in dotenv values
- filterChildShellEnv now also filters Bun-autoloaded .env.{NODE_ENV||development}
  entries, closing the .env.production/.env.development leak into child shells.
- parseEnvLine skips backslash-escaped quotes when locating the closing
  delimiter, restoring baseline/Bun-literal handling of values like JSON="{\"a\":1}"
  that the new parser truncated.
- Adds a parseEnvFile regression test for escaped quotes.
2026-07-28 10:58:59 +02:00
can1357 0a5727670f Merge PR #6814: fix(cli): stop forwarding project dotenv to shells (@roboomp) 2026-07-28 10:58:59 +02:00
can1357 c307f7361a fix: fall back to musl libc soname when loading prctl 2026-07-28 10:58:58 +02:00
roboomp b9f1c32f69 fix(utils): parsed dotenv with bun-compatible syntax
Handled export prefixes and quote-aware inline comments when parsing dotenv files, and filtered child shells by launcher provenance so injected values are dropped regardless of value formatting.

Covered export and inline-comment forms in unit and shell-filter tests.

Fixes #6813
2026-07-27 15:37:13 +00:00
roboomp 048b415670 fix(utils): preserved launcher-owned shell variables
Tracked project values loaded by OMP separately from names present in the original launch environment, preserving parent values even when dotenv repeats the same bytes.

Covered Bun-autoloaded and no-env-file launch modes.

Fixes #6813
2026-07-27 15:31:46 +00:00
roboomp 2860abadaf fix(cli): set kernel process name via prctl on linux
Bun's `process.title` setter is a JS-level no-op: it stores the value
internally but never calls `prctl(PR_SET_NAME)`, so `omp` appeared as
`bun` in ps/pgrep/killall/top and `pkill bun` became a footgun killing
every Bun process. Add `setProcessName` in pi-utils that also drives
prctl via bun:ffi on Linux, and use it at CLI startup and in the daemon
broker.

Fixes #6815
2026-07-27 15:28:59 +00:00
roboomp bc63b357b3 fix(utils): expanded dotenv values before shell filtering
Matched both raw OMP-loaded values and Bun-expanded project values when removing launch dotenv entries from child shell environments.

Covered Bun autoload and no-env-file execution modes.

Fixes #6813
2026-07-27 15:23:58 +00:00
roboomp f13ee64c27 fix(cli): stopped forwarding project dotenv to shells
Filtered launch-directory .env and .env.local values from the base shell environment while preserving explicit per-command overrides.

Expanded the shell environment regression test across both dotenv files.

Fixes #6813
2026-07-27 15:15:07 +00:00
can1357 f8dbb3669f feat(utils): implemented windows shell resolution for bash execution
- Added resolveWindowsShell to locate Git Bash, scoop installs, and path binaries with a fallback to cmd.exe.
- Updated bash-executor to prevent wrapping user commands in cmd.exe when using fallback shell paths.
- Updated installation script to report optional shell status rather than failing when bash is absent.
2026-07-26 20:27:16 +02:00
can1357 aaa31eca32 fix(utils): surface invalid shellPath even when a shell config is cached
- getShellConfig returned the module cache before validating customShellPath, so a broken configured shell was silently masked once any earlier caller resolved a shell in the same process; PR #6581's settings-manager tests exposed the ordering under the full suite.
- A differing valid customShellPath now rebuilds the cached config instead of being ignored.
2026-07-26 16:06:19 +02:00
can1357 a6dfc78c73 Merge PR #6644: fix(utils): contain ptree timeout rejections (@roboomp) 2026-07-26 15:45:10 +02:00
can1357 fb38343a89 Merge PR #6581: fix(utils): correct shell path config guidance (@roboomp) 2026-07-26 15:45:09 +02:00
can1357 9b8715ee78 Merge PR #6493: fix(coding-agent): bypass extension guards during shutdown (@roboomp) 2026-07-26 15:41:31 +02:00
roboomp 8376555099 fix(utils): contained ptree timeout rejections
- Observed timed-out child lifecycle failures without altering awaited rejection semantics.
- Added coverage for callers that settle without observing the lifecycle promise.

Fixes #6635
2026-07-25 20:17:08 +00:00
usr-bin-roygbiv 9ceebb2a4d fix(workers): isolate compiled host selectors 2026-07-25 08:31:54 +00:00
roboomp ca0d3e3e5b fix(config): resolved shell setting source paths
Tracked the effective global, project, overlay, or runtime source of shellPath so resolution errors identify the configuration users must edit.

Covered custom agent directories and higher-precedence settings layers with focused regressions.

Fixes #6579
2026-07-25 05:32:40 +00:00
roboomp b363d2a93d fix(utils): corrected shell path config guidance
Updated Windows shell resolution errors to point at the canonical config.yml file instead of the migration-only settings.json path.

Added a regression test for the invalid custom shell path error.

Fixes #6579
2026-07-25 05:21:40 +00:00
usr-bin-roygbiv f1fb05df80 fix(eval): statically link rejection interceptor 2026-07-25 04:24:25 +00:00
roboomp c9363e2884 fix(utils): kept public quit behind host guard
Routed postmortem.quit through the mutable process.exit path while retaining captured native exits for host-owned shutdown.

Added child-process coverage proving guarded postmortem.quit calls surface ExtensionExitError without terminating the host.

Fixes #6488
2026-07-24 07:41:36 +00:00
roboomp e09eda00cd fix(coding-agent): bypassed extension guard for shutdown
- Captured the native hard-exit function for postmortem signal, fatal, and manual exits.
- Added bounded child-process coverage for SIGINT and fatal cleanup during pending guarded loads.
- Preserved extension and hook exit isolation and made the EPIPE race assertion observe the real exit event.

Fixes #6488
2026-07-24 07:26:22 +00:00
can1357 7eeaba0471 refactor(coding-agent/session): restructured monolithic agent session
- Extracted internal handlers and logic from AgentSession into dedicated runner, guard, and coordinator modules.
- Created standalone modules for bash execution, evaluation runners, IRC bridging, and prewalk coordination.
- Established dedicated session components for tracking stats, todos, streams, and retry fallback chains.
- Preserved existing session behavior while significantly reducing monolithic class size and complexity.
2026-07-24 01:24:44 +02:00
can1357 0f54c0df70 fix(tools): autoqa consent handling from default off to opt-in 2026-07-23 13:24:45 +02:00
can1357 ac8e9e05bb fix(utils): made runtime module resolver uninstallable
installRuntimeModuleResolver patched Module._resolveFilename process-wide
with no way back. In the shared bun test process the leaked patch broke
createRequire relative requires for every later test file (Bun 1.3.14 calls
a JS _resolveFilename override with parent === undefined, so './x' resolves
'from ""'), failing legacy-pi-inplace-load only in full-suite runs.

The installer now returns an uninstaller that drops the registration and
restores the pristine resolver when no runtime roots remain; the known Bun
limitation is documented so the patch stays scoped to worker runtimes.
2026-07-18 22:17:04 +02:00
roboomp 53a3aef39a fix(subagent): keep title refresh for focusable subagents
Review follow-up: a live subagent focused from the Agent Hub renders its
session name in the status line (session_name segment reads
sessionManager.getSessionName()), so the blanket agentKind === "sub" skip
made the user-enabled title.refreshOnReplan silently ineffective and left
focused subagents untitled after their first todo replan.

Focus only exists in an interactive host, and subagents run in-process, so
gate the skip on a process-global interactive-host flag: subagents skip the
replan title refresh only in non-interactive hosts (print/RPC/ACP/eval/SDK/
CI) where no session tree is focusable. The interactive entrypoint declares
the host via setInteractiveHost(isInteractive); the flag defaults false, so
bun test and headless embedders keep the optimization without leaking state.

Fixes #5910
2026-07-17 21:10:58 +00:00
can1357 adb2a3c7e2 style: formatted files from owner-approved merges 2026-07-17 05:33:19 +02:00
can1357 92d63050c0 merge sweep/2026-07-17 2026-07-17 05:24:45 +02:00
can1357 f92d8feeec merge PR #5761 via eval/pr-5761: fix(utils): bounded default ptree stderr retention 2026-07-17 04:42:10 +02:00
roboomp edba577e7a fix(utils): bounded default ptree stderr retention
Default ChildProcess unconditionally pushed every raw stderr chunk into
`#stderrChunks`, so long-lived noisy subprocesses (LSP/DAP/RPC) grew OMP
memory linearly despite the 32 KiB visible tail cap.

- Allocate `#stderrChunks` only when full capture is requested at spawn.
- Decouple retention from stream exposure via `spawnInternal`, so
  `exec({ stderr: "full" })` retains without an unused live tee.
- Reject retroactive `wait({ stderr: "full" })` on a default child with a
  clear error instead of returning truncated data.

Fixes #5759
2026-07-16 21:41:44 +00:00
roboomp 7b5d936f95 fix(utils): pruned stale pid log namespaces
Kept live process logs isolated while globally retaining only the five newest files from completed processes.

Removed one-use audit files after their owning process exits and covered short-lived invocation cleanup.

Fixes #5716
2026-07-16 14:56:28 +00:00
roboomp 7550bd887c fix(utils): isolated fatal logging teardown
Made fatal reporting bypass revoked stderr streams and armed a referenced forced-exit watchdog around bounded cleanup.

Separated rotating log and audit namespaces by PID and disabled compression pipelines so concurrent TUI processes cannot race shared rotation state.

Fixes #5716
2026-07-16 14:46:40 +00:00
can1357 f7ed718302 fix(utils): share active postmortem cleanup 2026-07-16 03:50:06 +02:00
can1357 fd54f897f4 merged PR #5419: fix(acp): await teardown on stdio disconnect
# Conflicts:
#	packages/coding-agent/src/modes/acp/acp-mode.ts
2026-07-16 03:50:06 +02:00
can1357 362f89a2ec Merge remote-tracking branch 'origin/farm/fe301a84/reduce-stream-decoding-cpu' 2026-07-15 09:54:59 +02:00
can1357 404ebb0fb0 Merge remote-tracking branch 'origin/farm/ae7a5593/ttsr-inline-regex-flags-and-scope-quoting' 2026-07-15 09:54:46 +02:00
roboomp 22fa8f6623 perf(stream): batched response decoding
- Batched complete SSE lines into one UTF-8 decode per source chunk.

- Parsed Ollama NDJSON bytes directly without TextDecoder buffering.

Fixes #5542
2026-07-15 02:55:02 +00:00
can1357 0418d8622a fix(cli): handle native parser usage errors 2026-07-14 23:11:11 +02:00
can1357 33f61cc511 Merge PR #5496: fix(cli): print concise usage error instead of source dump (@roboomp) 2026-07-14 23:11:11 +02:00
roboomp 506d0942cf feat(telemetry): added otlp log and metric export
Extended the OTLP export bootstrap beyond traces so omp emits the full
OpenTelemetry signal set from a single session.

- Registered a LoggerProvider + BatchLogRecordProcessor and a MeterProvider
  + PeriodicExportingMetricReader when their OTLP endpoints (or the shared
  endpoint) are set, each gated independently by OTEL_*_EXPORTER=none,
  OTEL_SDK_DISABLED, and http/protobuf protocol checks.
- Bridged the centralized logger through a new registerLogSink API so every
  log event also becomes an OTLP log record with severity, attributes, and
  active span context for log-trace correlation (min level via OTEL_LOG_LEVEL).
- Recorded gen_ai.client.token.usage and pi.omp.agent.* metrics from the
  agent run summary and per-chat usage hooks, and emitted a structured run
  summary log event.
- Added an out-of-process logs+metrics probe and gating tests covering the
  per-signal kill switches.

Fixes #4604
2026-07-14 19:39:11 +00:00
roboomp 6dc48a8b02 fix(cli): print concise usage error instead of source dump
Argument/flag validation failures in the minimal CLI framework threw a
plain Error that bubbled to the process-level catch in cli.ts, which
dumps a Bun.inspect code frame — a minified dist/cli.js excerpt in
compiled binaries. A missing model on `omp bench` looked like a crash.

- Add CliUsageError; throw it from Command.parse for missing/invalid
  args and flags.
- Catch CliUsageError in run(): print `error: <msg>` plus the command
  usage line to stderr, exit 1, no stack.
- Render required variadic positionals as MODELS... in usage, not the
  misleading optional [MODELS]; extract commandUsageLine helper.

Fixes #5369
2026-07-14 19:16:59 +00:00
roboomp 86824c94e9 fix(ttsr): registered rules with inline regex flags and malformed scope
Rules whose condition led with a PCRE-style inline flag group (e.g.
`(?i)`) never registered: `new RegExp("(?i)...")` throws in Bun/JS, so
the condition failed to compile and `TtsrManager.addRule` dropped the
rule as having zero usable conditions.

- Add `compileRuleCondition` in capability/rule.ts translating a leading
  `(?i)`/`(?m)`/`(?s)` group into native RegExp flags; wire it into the
  TtsrManager and both ttsr-cli compile sites.
- Strip surrounding quotes from scope tokens so a malformed
  `scope: "text","thinking"` recovers to canonical `text`/`thinking`.
- Reparse each value in parseFrontmatter's YAML fallback so one bad line
  can't leave sibling values wrapped in literal quotes.

Fixes #4796
2026-07-14 19:01:47 +00:00
can1357 3efbce97b5 Merge PR #5295: fix(utils): bound Mermaid ASCII pathfinder (@roboomp) 2026-07-14 19:16:08 +02:00
can1357 c8afd0f967 Merge PR #5131: fix(tui): suppress unmanaged macOS stderr writes corrupting the viewport (@korri123) 2026-07-14 18:34:14 +02:00
roboomp 953859d956 fix(acp): awaited teardown on stdio disconnect
Registered ACP session disposal with postmortem and replaced the hard EOF exit with the awaited graceful shutdown path.

Classified stdio-write EPIPE separately from worker IPC EPIPE so ACP peer loss exits successfully after cleanup.

Fixes #4788
2026-07-14 16:20:48 +00:00
roboomp cc2041ab7f fix(utils): bounded mermaid ascii pathfinder
- Added bounded A* routing extents plus an expansion backstop so unreachable attachment points return null instead of searching the unbounded quadrant.
- Covered the reported declaration-order graph and an enclosed destination attachment point.
- Documented the Mermaid ASCII routing fix in the utils changelog.

Fixes #5293
2026-07-12 18:54:28 +00:00
can1357 a3117c2842 feat(agent): migrated async-drain utility to shared package for reuse
- Relocated `AsyncDrain` class from `coding-agent` to `utils` package.
- Updated `HistoryStorage` to import `AsyncDrain` from shared utilities.
- Centralized the utility to allow reuse across the codebase.
2026-07-12 01:06:17 +02:00
Kormákur 17486d2009 fix(utils): create log dir before redirecting stderr guard
On a fresh profile ~/.omp/logs may not exist yet (the logger creates it
lazily), so opening getLogPath() with "a" threw and the guard fell back to
/dev/null — discarding macOS diagnostics and native crash reports instead
of preserving them in the omp log. mkdir the redirect target's parent
(recursive) before opening; the /dev/null fallback stays as the safety net.
2026-07-11 00:38:55 +00:00
Kormákur 4eaca82fa6 fix(tui): suppress unmanaged macOS stderr writes corrupting the viewport
On macOS, libmalloc writes runtime diagnostics (e.g. "MallocStackLogging:
can't turn off malloc stack logging because it was not enabled") directly
to fd 2 of the running TUI process at arbitrary times, painting into the
viewport. The existing env-strip only protects child processes.

Add a fd-level stderr guard in pi-utils (suppressTerminalStderr /
restoreTerminalStderr) that dup2-redirects fd 2 to the omp log file while
the TUI owns the terminal, and restores it at every ownership handoff
(external editor, Ctrl+Z suspend, shutdown, crash restore). Postmortem
fatal handlers restore fd 2 before printing so crash reports stay visible.

Mirrors openai/codex#24459.
2026-07-11 00:16:42 +00:00
can1357 531880c620 feat: improved json serialization for bigint values
- Introduced `stringifyJson` helper to preserve bigint precision by serializing them as decimal strings.
- Replaced native `JSON.stringify` across compaction and session management modules to prevent serialization errors when handling bigint values in tool arguments.
- Added regression tests in `agent` and `coding-agent` packages to ensure bigint tool arguments remain intact through compaction and persistence flows.
2026-07-11 00:12:29 +02:00